CVE-2025-3609
The Reales WP STPT plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 2.1.2. This is due to the 'reales_user_signup_form' AJAX action not verifying if user registration is enabled, prior to registering a user. This makes it possible for unauthenticated attackers to create new user accounts, which can be leveraged with CVE-XX to achieve privilege escalation.
Vendor
-
Product
-
CWE
Yayın Tarihi
2025-05-06 03:15:17
Güncelleme
2025-05-07 14:13:35
Source Identifier
security@wordfence.com
KEV Date Added
-